TL;DR: Shadow AI is spreading faster than most organisations can govern it, according to JumpCloud, with IBM’s 2025 breach research saying 63% lacked formal AI guidelines and leaving data exposed outside intended boundaries. Existing IAM and device controls help, but AI governance still needs explicit policy, oversight, and usage discipline.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Beyond the Hype: How Your Existing Controls Are the True Foundation of AI Governance”.
By the numbers:
- 63% of organisations lacked formal guidelines for managing AI, failing to prevent the use of shadow AI.
Key questions
Q: How should security teams govern shadow AI without blocking business productivity?
A: Start by identifying the identities and credentials behind AI use, then classify each one by data sensitivity, connected systems, and business purpose.
Q: Why do existing IAM controls only partially solve AI governance?
A: IAM decides who can reach a service, but AI governance also has to control what data is submitted and how the service may use it.
Q: What breaks when employees use unapproved AI tools with company data?
A: Governance breaks because the organisation loses visibility into where data and secrets are going, who can access them, and how they are being reused.
Practitioner guidance
- Define an approved AI use policy Specify which AI services are allowed, what data may be used, and which work contexts require prior approval.
- Extend IAM rules to AI tool access Map identity groups to AI service access tiers, then require explicit authorisation for tools that process source code, regulated data, or internal documents.
- Use endpoint posture to block unmanaged AI use Tie device compliance, inventory, and patch status to access conditions for AI services.
Bottom line: Shadow AI is the clearest sign that AI governance cannot rely on IAM alone, because authentication does not control what users submit to external AI services.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shadow AI is an identity governance failure before it is an AI problem. The article correctly points to unmanaged adoption, but the deeper issue is that enterprise controls were designed for approved software paths, not for employees creating new data egress routes through third-party models. When the access path is invisible, governance cannot certify what it cannot see. The practitioner conclusion is that AI usage must be brought under identity and device control before policy can mean anything.
A few things that frame the scale:
- 72% of organizations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks.
A question worth separating out:
Q: How can security teams reduce AI data leakage from managed endpoints?
A: Use device management to restrict which endpoints can access approved AI services, require patching and inventory visibility, and block unmanaged browsers or devices from handling sensitive workflows. The goal is to stop data from leaving through an endpoint that cannot be inspected or governed. That makes containment possible before the prompt is sent.
👉 Read our full editorial: AI governance is exposing the limits of existing IAM controls
Shadow AI is an identity governance problem before it is an AI problem: unmanaged AI use emerges when users can move from approved identity to unapproved data processing without a new control decision. Existing IAM can authenticate the user, but it does not automatically govern the AI endpoint or the data submitted to it. The implication is that AI governance must start with user-to-tool authorisation, not only with model oversight.
A few things that frame the scale:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How do organisations know if AI identity governance is working?
A: They should be able to answer three questions quickly: which agents exist, which credentials each one uses, and who is accountable for each identity’s lifecycle. If any of those answers require manual searching across teams, the governance model is still incomplete and the environment remains difficult to audit.
👉 Read our full editorial: AI governance is exposing the limits of existing IAM controls